Policy Commands

Table 1-12 shows new and changed Policy Commands in Release 4.0.1:

Table 1-12: Policy Commands

Old Command

New Command

New Definition/Argument

To Enable:

N/A

There is no default.

ip access-group

 

 

<access-list-name>

 

 

[default-action-deny]

 

 

To Disable:

 

 

[no] ip access-group

 

 

 

 

 

To Enable:

To Enable:

<protocol-id> – name or

 

[ip] access-list

number of an IP protocol. It can be

ip access-list

<access-list-name>

one of the keywords eigrp, gre,

<access-list-name>

<access-list-index>

icmp, igmp, igrp, ip, ipinip, nos,

<access-list-index>

{permitdenyfwd1-8}

ospf, tcp, or udp, or an integer in

{permitdenyfwd[1-8]}

<protocol-id>{<source-

the range 0 to 255 representing an

{<source-ip-addr>

ip-addr> <source-

IP protocol number. To match any

[<source-wildcard>]

wildcard>anyhost

Internet protocol (including ICMP,

anyhost <source-ip-

<source-ip-addr> }

TCP, and UDP) use the keyword

addr>}

[{lteqgtrange}

ip.

 

<port> [<port>]]

<dest-ip-addr> – number of

 

{<dest-ip-addr> <dest-

the network or host to which the

 

wildcard> any host

packet is being sent. Use a 32-bit

 

<dest-ip-addr> }

quantity in four-part, dotted-

 

[{lteqgtrange}

decimal format. Use the keyword

 

<port> [<port>]]

any as an abbreviation for a dest

 

[established]

and dest -wildcard of 0.0.0.0 and

 

 

255.255.255.255. Use "host <dest-

 

 

ip-addr>" as an abbreviation for a

 

 

destination with dest-wildcard of

 

 

0.0.0.0.

 

 

 

To Disable:

To Disable:

<dest-wildcard> – wildcard

[no] ip access-list

N/A

bits to be applied to the

<access-list-name>

 

destination. Use a 32-bit quantity

[<access-list-index>]

 

in four-part, dotted-decimal

 

 

format. Place ones in the bit

 

 

positions you want to ignore.

 

 

operator – (Optional) Compares

 

 

source or destination ports.

 

 

Possible operands include: lt = less

 

 

than, gt =greater than, eq=equal,

 

 

neq =not equal, and range

 

 

=inclusive range.

 

 

If the operator is positioned after the

 

 

source and source-wildcard, it must

 

 

match the source port.

 

 

If the operator is positioned after the

 

 

destination and destination-wildcard,

 

 

it must match the destination port.

 

 

 

Cajun P220, P550, P550R Switch Release Notes, Release 4.0.1

35

Page 35
Image 35
Lucent Technologies P550R, P220 manual Policy Commands